PT-2000-1758 · Sambar · Search.Dll Sambar Isapi Search Utility+1
Published
2000-11-14
·
Updated
2010-01-16
·
CVE-2000-0835
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sambar Server version 4.4 Beta 3
Description
The issue allows remote attackers to read arbitrary directories by specifying the directory in the
query parameter of the search.dll Sambar ISAPI Search utility.Recommendations
For Sambar Server version 4.4 Beta 3, consider restricting access to the search.dll Sambar ISAPI Search utility until a patch is available. As a temporary workaround, avoid using the
query parameter in the affected API endpoint.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sambar Server
Search.Dll Sambar Isapi Search Utility